3 use BookStack\Http\Controllers\Api;
4 use BookStack\Http\Controllers\AttachmentController;
5 use BookStack\Http\Controllers\AuditLogController;
6 use BookStack\Http\Controllers\Auth;
7 use BookStack\Http\Controllers\BookController;
8 use BookStack\Http\Controllers\BookExportController;
9 use BookStack\Http\Controllers\BookshelfController;
10 use BookStack\Http\Controllers\BookSortController;
11 use BookStack\Http\Controllers\ChapterController;
12 use BookStack\Http\Controllers\ChapterExportController;
13 use BookStack\Http\Controllers\CommentController;
14 use BookStack\Http\Controllers\FavouriteController;
15 use BookStack\Http\Controllers\HomeController;
16 use BookStack\Http\Controllers\Images;
17 use BookStack\Http\Controllers\MaintenanceController;
18 use BookStack\Http\Controllers\PageController;
19 use BookStack\Http\Controllers\PageExportController;
20 use BookStack\Http\Controllers\PageRevisionController;
21 use BookStack\Http\Controllers\PageTemplateController;
22 use BookStack\Http\Controllers\PermissionsController;
23 use BookStack\Http\Controllers\RecycleBinController;
24 use BookStack\Http\Controllers\ReferenceController;
25 use BookStack\Http\Controllers\RoleController;
26 use BookStack\Http\Controllers\SearchController;
27 use BookStack\Http\Controllers\SettingController;
28 use BookStack\Http\Controllers\StatusController;
29 use BookStack\Http\Controllers\TagController;
30 use BookStack\Http\Controllers\UserApiTokenController;
31 use BookStack\Http\Controllers\UserController;
32 use BookStack\Http\Controllers\UserPreferencesController;
33 use BookStack\Http\Controllers\UserProfileController;
34 use BookStack\Http\Controllers\UserSearchController;
35 use BookStack\Http\Controllers\WebhookController;
36 use BookStack\Http\Middleware\VerifyCsrfToken;
37 use Illuminate\Session\Middleware\StartSession;
38 use Illuminate\Support\Facades\Route;
39 use Illuminate\View\Middleware\ShareErrorsFromSession;
41 Route::get('/status', [StatusController::class, 'show']);
42 Route::get('/robots.txt', [HomeController::class, 'robots']);
43 Route::get('/favicon.ico', [HomeController::class, 'favicon']);
45 // Authenticated routes...
46 Route::middleware('auth')->group(function () {
48 // Secure images routing
49 Route::get('/uploads/images/{path}', [Images\ImageController::class, 'showImage'])
50 ->where('path', '.*$');
53 Route::redirect('/api', '/api/docs');
54 Route::get('/api/docs', [Api\ApiDocsController::class, 'display']);
56 Route::get('/pages/recently-updated', [PageController::class, 'showRecentlyUpdated']);
59 Route::get('/create-shelf', [BookshelfController::class, 'create']);
60 Route::get('/shelves/', [BookshelfController::class, 'index']);
61 Route::post('/shelves/', [BookshelfController::class, 'store']);
62 Route::get('/shelves/{slug}/edit', [BookshelfController::class, 'edit']);
63 Route::get('/shelves/{slug}/delete', [BookshelfController::class, 'showDelete']);
64 Route::get('/shelves/{slug}', [BookshelfController::class, 'show']);
65 Route::put('/shelves/{slug}', [BookshelfController::class, 'update']);
66 Route::delete('/shelves/{slug}', [BookshelfController::class, 'destroy']);
67 Route::get('/shelves/{slug}/permissions', [PermissionsController::class, 'showForShelf']);
68 Route::put('/shelves/{slug}/permissions', [PermissionsController::class, 'updateForShelf']);
69 Route::post('/shelves/{slug}/copy-permissions', [PermissionsController::class, 'copyShelfPermissionsToBooks']);
70 Route::get('/shelves/{slug}/references', [ReferenceController::class, 'shelf']);
73 Route::get('/shelves/{shelfSlug}/create-book', [BookController::class, 'create']);
74 Route::post('/shelves/{shelfSlug}/create-book', [BookController::class, 'store']);
75 Route::get('/create-book', [BookController::class, 'create']);
78 Route::get('/books/', [BookController::class, 'index']);
79 Route::post('/books/', [BookController::class, 'store']);
80 Route::get('/books/{slug}/edit', [BookController::class, 'edit']);
81 Route::put('/books/{slug}', [BookController::class, 'update']);
82 Route::delete('/books/{id}', [BookController::class, 'destroy']);
83 Route::get('/books/{slug}/sort-item', [BookSortController::class, 'showItem']);
84 Route::get('/books/{slug}', [BookController::class, 'show']);
85 Route::get('/books/{bookSlug}/permissions', [PermissionsController::class, 'showForBook']);
86 Route::put('/books/{bookSlug}/permissions', [PermissionsController::class, 'updateForBook']);
87 Route::get('/books/{slug}/delete', [BookController::class, 'showDelete']);
88 Route::get('/books/{bookSlug}/copy', [BookController::class, 'showCopy']);
89 Route::post('/books/{bookSlug}/copy', [BookController::class, 'copy']);
90 Route::post('/books/{bookSlug}/convert-to-shelf', [BookController::class, 'convertToShelf']);
91 Route::get('/books/{bookSlug}/sort', [BookSortController::class, 'show']);
92 Route::put('/books/{bookSlug}/sort', [BookSortController::class, 'update']);
93 Route::get('/books/{slug}/references', [ReferenceController::class, 'book']);
94 Route::get('/books/{bookSlug}/export/html', [BookExportController::class, 'html']);
95 Route::get('/books/{bookSlug}/export/pdf', [BookExportController::class, 'pdf']);
96 Route::get('/books/{bookSlug}/export/markdown', [BookExportController::class, 'markdown']);
97 Route::get('/books/{bookSlug}/export/zip', [BookExportController::class, 'zip']);
98 Route::get('/books/{bookSlug}/export/plaintext', [BookExportController::class, 'plainText']);
101 Route::get('/books/{bookSlug}/create-page', [PageController::class, 'create']);
102 Route::post('/books/{bookSlug}/create-guest-page', [PageController::class, 'createAsGuest']);
103 Route::get('/books/{bookSlug}/draft/{pageId}', [PageController::class, 'editDraft']);
104 Route::post('/books/{bookSlug}/draft/{pageId}', [PageController::class, 'store']);
105 Route::get('/books/{bookSlug}/page/{pageSlug}', [PageController::class, 'show']);
106 Route::get('/books/{bookSlug}/page/{pageSlug}/export/pdf', [PageExportController::class, 'pdf']);
107 Route::get('/books/{bookSlug}/page/{pageSlug}/export/html', [PageExportController::class, 'html']);
108 Route::get('/books/{bookSlug}/page/{pageSlug}/export/markdown', [PageExportController::class, 'markdown']);
109 Route::get('/books/{bookSlug}/page/{pageSlug}/export/plaintext', [PageExportController::class, 'plainText']);
110 Route::get('/books/{bookSlug}/page/{pageSlug}/edit', [PageController::class, 'edit']);
111 Route::get('/books/{bookSlug}/page/{pageSlug}/move', [PageController::class, 'showMove']);
112 Route::put('/books/{bookSlug}/page/{pageSlug}/move', [PageController::class, 'move']);
113 Route::get('/books/{bookSlug}/page/{pageSlug}/copy', [PageController::class, 'showCopy']);
114 Route::post('/books/{bookSlug}/page/{pageSlug}/copy', [PageController::class, 'copy']);
115 Route::get('/books/{bookSlug}/page/{pageSlug}/delete', [PageController::class, 'showDelete']);
116 Route::get('/books/{bookSlug}/draft/{pageId}/delete', [PageController::class, 'showDeleteDraft']);
117 Route::get('/books/{bookSlug}/page/{pageSlug}/permissions', [PermissionsController::class, 'showForPage']);
118 Route::put('/books/{bookSlug}/page/{pageSlug}/permissions', [PermissionsController::class, 'updateForPage']);
119 Route::get('/books/{bookSlug}/page/{pageSlug}/references', [ReferenceController::class, 'page']);
120 Route::put('/books/{bookSlug}/page/{pageSlug}', [PageController::class, 'update']);
121 Route::delete('/books/{bookSlug}/page/{pageSlug}', [PageController::class, 'destroy']);
122 Route::delete('/books/{bookSlug}/draft/{pageId}', [PageController::class, 'destroyDraft']);
125 Route::get('/books/{bookSlug}/page/{pageSlug}/revisions', [PageRevisionController::class, 'index']);
126 Route::get('/books/{bookSlug}/page/{pageSlug}/revisions/{revId}', [PageRevisionController::class, 'show']);
127 Route::get('/books/{bookSlug}/page/{pageSlug}/revisions/{revId}/changes', [PageRevisionController::class, 'changes']);
128 Route::put('/books/{bookSlug}/page/{pageSlug}/revisions/{revId}/restore', [PageRevisionController::class, 'restore']);
129 Route::delete('/books/{bookSlug}/page/{pageSlug}/revisions/{revId}/delete', [PageRevisionController::class, 'destroy']);
132 Route::get('/books/{bookSlug}/chapter/{chapterSlug}/create-page', [PageController::class, 'create']);
133 Route::post('/books/{bookSlug}/chapter/{chapterSlug}/create-guest-page', [PageController::class, 'createAsGuest']);
134 Route::get('/books/{bookSlug}/create-chapter', [ChapterController::class, 'create']);
135 Route::post('/books/{bookSlug}/create-chapter', [ChapterController::class, 'store']);
136 Route::get('/books/{bookSlug}/chapter/{chapterSlug}', [ChapterController::class, 'show']);
137 Route::put('/books/{bookSlug}/chapter/{chapterSlug}', [ChapterController::class, 'update']);
138 Route::get('/books/{bookSlug}/chapter/{chapterSlug}/move', [ChapterController::class, 'showMove']);
139 Route::put('/books/{bookSlug}/chapter/{chapterSlug}/move', [ChapterController::class, 'move']);
140 Route::get('/books/{bookSlug}/chapter/{chapterSlug}/copy', [ChapterController::class, 'showCopy']);
141 Route::post('/books/{bookSlug}/chapter/{chapterSlug}/copy', [ChapterController::class, 'copy']);
142 Route::get('/books/{bookSlug}/chapter/{chapterSlug}/edit', [ChapterController::class, 'edit']);
143 Route::post('/books/{bookSlug}/chapter/{chapterSlug}/convert-to-book', [ChapterController::class, 'convertToBook']);
144 Route::get('/books/{bookSlug}/chapter/{chapterSlug}/permissions', [PermissionsController::class, 'showForChapter']);
145 Route::get('/books/{bookSlug}/chapter/{chapterSlug}/export/pdf', [ChapterExportController::class, 'pdf']);
146 Route::get('/books/{bookSlug}/chapter/{chapterSlug}/export/html', [ChapterExportController::class, 'html']);
147 Route::get('/books/{bookSlug}/chapter/{chapterSlug}/export/markdown', [ChapterExportController::class, 'markdown']);
148 Route::get('/books/{bookSlug}/chapter/{chapterSlug}/export/plaintext', [ChapterExportController::class, 'plainText']);
149 Route::put('/books/{bookSlug}/chapter/{chapterSlug}/permissions', [PermissionsController::class, 'updateForChapter']);
150 Route::get('/books/{bookSlug}/chapter/{chapterSlug}/references', [ReferenceController::class, 'chapter']);
151 Route::get('/books/{bookSlug}/chapter/{chapterSlug}/delete', [ChapterController::class, 'showDelete']);
152 Route::delete('/books/{bookSlug}/chapter/{chapterSlug}', [ChapterController::class, 'destroy']);
154 // User Profile routes
155 Route::get('/user/{slug}', [UserProfileController::class, 'show']);
158 Route::get('/images/gallery', [Images\GalleryImageController::class, 'list']);
159 Route::post('/images/gallery', [Images\GalleryImageController::class, 'create']);
160 Route::get('/images/drawio', [Images\DrawioImageController::class, 'list']);
161 Route::get('/images/drawio/base64/{id}', [Images\DrawioImageController::class, 'getAsBase64']);
162 Route::post('/images/drawio', [Images\DrawioImageController::class, 'create']);
163 Route::get('/images/edit/{id}', [Images\ImageController::class, 'edit']);
164 Route::put('/images/{id}', [Images\ImageController::class, 'update']);
165 Route::delete('/images/{id}', [Images\ImageController::class, 'destroy']);
167 // Attachments routes
168 Route::get('/attachments/{id}', [AttachmentController::class, 'get']);
169 Route::post('/attachments/upload', [AttachmentController::class, 'upload']);
170 Route::post('/attachments/upload/{id}', [AttachmentController::class, 'uploadUpdate']);
171 Route::post('/attachments/link', [AttachmentController::class, 'attachLink']);
172 Route::put('/attachments/{id}', [AttachmentController::class, 'update']);
173 Route::get('/attachments/edit/{id}', [AttachmentController::class, 'getUpdateForm']);
174 Route::get('/attachments/get/page/{pageId}', [AttachmentController::class, 'listForPage']);
175 Route::put('/attachments/sort/page/{pageId}', [AttachmentController::class, 'sortForPage']);
176 Route::delete('/attachments/{id}', [AttachmentController::class, 'delete']);
179 Route::put('/ajax/page/{id}/save-draft', [PageController::class, 'saveDraft']);
180 Route::get('/ajax/page/{id}', [PageController::class, 'getPageAjax']);
181 Route::delete('/ajax/page/{id}', [PageController::class, 'ajaxDestroy']);
184 Route::get('/tags', [TagController::class, 'index']);
185 Route::get('/ajax/tags/suggest/names', [TagController::class, 'getNameSuggestions']);
186 Route::get('/ajax/tags/suggest/values', [TagController::class, 'getValueSuggestions']);
189 Route::post('/comment/{pageId}', [CommentController::class, 'savePageComment']);
190 Route::put('/comment/{id}', [CommentController::class, 'update']);
191 Route::delete('/comment/{id}', [CommentController::class, 'destroy']);
194 Route::get('/link/{id}', [PageController::class, 'redirectFromLink']);
197 Route::get('/search', [SearchController::class, 'search']);
198 Route::get('/search/book/{bookId}', [SearchController::class, 'searchBook']);
199 Route::get('/search/chapter/{bookId}', [SearchController::class, 'searchChapter']);
200 Route::get('/search/entity/siblings', [SearchController::class, 'searchSiblings']);
201 Route::get('/search/entity-selector', [SearchController::class, 'searchForSelector']);
202 Route::get('/search/suggest', [SearchController::class, 'searchSuggestions']);
205 Route::get('/search/users/select', [UserSearchController::class, 'forSelect']);
208 Route::get('/templates', [PageTemplateController::class, 'list']);
209 Route::get('/templates/{templateId}', [PageTemplateController::class, 'get']);
212 Route::get('/favourites', [FavouriteController::class, 'index']);
213 Route::post('/favourites/add', [FavouriteController::class, 'add']);
214 Route::post('/favourites/remove', [FavouriteController::class, 'remove']);
217 Route::get('/', [HomeController::class, 'index']);
218 Route::get('/home', [HomeController::class, 'index']);
221 Route::get('/permissions/form-row/{entityType}/{roleId}', [PermissionsController::class, 'formRowForRole']);
224 Route::get('/settings/maintenance', [MaintenanceController::class, 'index']);
225 Route::delete('/settings/maintenance/cleanup-images', [MaintenanceController::class, 'cleanupImages']);
226 Route::post('/settings/maintenance/send-test-email', [MaintenanceController::class, 'sendTestEmail']);
227 Route::post('/settings/maintenance/regenerate-references', [MaintenanceController::class, 'regenerateReferences']);
230 Route::get('/settings/recycle-bin', [RecycleBinController::class, 'index']);
231 Route::post('/settings/recycle-bin/empty', [RecycleBinController::class, 'empty']);
232 Route::get('/settings/recycle-bin/{id}/destroy', [RecycleBinController::class, 'showDestroy']);
233 Route::delete('/settings/recycle-bin/{id}', [RecycleBinController::class, 'destroy']);
234 Route::get('/settings/recycle-bin/{id}/restore', [RecycleBinController::class, 'showRestore']);
235 Route::post('/settings/recycle-bin/{id}/restore', [RecycleBinController::class, 'restore']);
238 Route::get('/settings/audit', [AuditLogController::class, 'index']);
241 Route::get('/settings/users', [UserController::class, 'index']);
242 Route::get('/settings/users/create', [UserController::class, 'create']);
243 Route::get('/settings/users/{id}/delete', [UserController::class, 'delete']);
244 Route::post('/settings/users/create', [UserController::class, 'store']);
245 Route::get('/settings/users/{id}', [UserController::class, 'edit']);
246 Route::put('/settings/users/{id}', [UserController::class, 'update']);
247 Route::delete('/settings/users/{id}', [UserController::class, 'destroy']);
250 Route::redirect('/preferences', '/');
251 Route::get('/preferences/shortcuts', [UserPreferencesController::class, 'showShortcuts']);
252 Route::put('/preferences/shortcuts', [UserPreferencesController::class, 'updateShortcuts']);
253 Route::patch('/preferences/change-view/{type}', [UserPreferencesController::class, 'changeView']);
254 Route::patch('/preferences/change-sort/{type}', [UserPreferencesController::class, 'changeSort']);
255 Route::patch('/preferences/change-expansion/{type}', [UserPreferencesController::class, 'changeExpansion']);
256 Route::patch('/preferences/toggle-dark-mode', [UserPreferencesController::class, 'toggleDarkMode']);
257 Route::patch('/preferences/update-code-language-favourite', [UserPreferencesController::class, 'updateCodeLanguageFavourite']);
258 Route::patch('/preferences/update-boolean', [UserPreferencesController::class, 'updateBooleanPreference']);
261 Route::get('/settings/users/{userId}/create-api-token', [UserApiTokenController::class, 'create']);
262 Route::post('/settings/users/{userId}/create-api-token', [UserApiTokenController::class, 'store']);
263 Route::get('/settings/users/{userId}/api-tokens/{tokenId}', [UserApiTokenController::class, 'edit']);
264 Route::put('/settings/users/{userId}/api-tokens/{tokenId}', [UserApiTokenController::class, 'update']);
265 Route::get('/settings/users/{userId}/api-tokens/{tokenId}/delete', [UserApiTokenController::class, 'delete']);
266 Route::delete('/settings/users/{userId}/api-tokens/{tokenId}', [UserApiTokenController::class, 'destroy']);
269 Route::get('/settings/roles', [RoleController::class, 'index']);
270 Route::get('/settings/roles/new', [RoleController::class, 'create']);
271 Route::post('/settings/roles/new', [RoleController::class, 'store']);
272 Route::get('/settings/roles/delete/{id}', [RoleController::class, 'showDelete']);
273 Route::delete('/settings/roles/delete/{id}', [RoleController::class, 'delete']);
274 Route::get('/settings/roles/{id}', [RoleController::class, 'edit']);
275 Route::put('/settings/roles/{id}', [RoleController::class, 'update']);
278 Route::get('/settings/webhooks', [WebhookController::class, 'index']);
279 Route::get('/settings/webhooks/create', [WebhookController::class, 'create']);
280 Route::post('/settings/webhooks/create', [WebhookController::class, 'store']);
281 Route::get('/settings/webhooks/{id}', [WebhookController::class, 'edit']);
282 Route::put('/settings/webhooks/{id}', [WebhookController::class, 'update']);
283 Route::get('/settings/webhooks/{id}/delete', [WebhookController::class, 'delete']);
284 Route::delete('/settings/webhooks/{id}', [WebhookController::class, 'destroy']);
287 Route::get('/settings', [SettingController::class, 'index'])->name('settings');
288 Route::get('/settings/{category}', [SettingController::class, 'category'])->name('settings.category');
289 Route::post('/settings/{category}', [SettingController::class, 'update']);
293 Route::middleware('mfa-setup')->group(function () {
294 Route::get('/mfa/setup', [Auth\MfaController::class, 'setup']);
295 Route::get('/mfa/totp/generate', [Auth\MfaTotpController::class, 'generate']);
296 Route::post('/mfa/totp/confirm', [Auth\MfaTotpController::class, 'confirm']);
297 Route::get('/mfa/backup_codes/generate', [Auth\MfaBackupCodesController::class, 'generate']);
298 Route::post('/mfa/backup_codes/confirm', [Auth\MfaBackupCodesController::class, 'confirm']);
300 Route::middleware('guest')->group(function () {
301 Route::get('/mfa/verify', [Auth\MfaController::class, 'verify']);
302 Route::post('/mfa/totp/verify', [Auth\MfaTotpController::class, 'verify']);
303 Route::post('/mfa/backup_codes/verify', [Auth\MfaBackupCodesController::class, 'verify']);
305 Route::delete('/mfa/{method}/remove', [Auth\MfaController::class, 'remove'])->middleware('auth');
307 // Social auth routes
308 Route::get('/login/service/{socialDriver}', [Auth\SocialController::class, 'login']);
309 Route::get('/login/service/{socialDriver}/callback', [Auth\SocialController::class, 'callback']);
310 Route::post('/login/service/{socialDriver}/detach', [Auth\SocialController::class, 'detach'])->middleware('auth');
311 Route::get('/register/service/{socialDriver}', [Auth\SocialController::class, 'register']);
313 // Login/Logout routes
314 Route::get('/login', [Auth\LoginController::class, 'getLogin']);
315 Route::post('/login', [Auth\LoginController::class, 'login']);
316 Route::post('/logout', [Auth\LoginController::class, 'logout']);
317 Route::get('/register', [Auth\RegisterController::class, 'getRegister']);
318 Route::get('/register/confirm', [Auth\ConfirmEmailController::class, 'show']);
319 Route::get('/register/confirm/awaiting', [Auth\ConfirmEmailController::class, 'showAwaiting']);
320 Route::post('/register/confirm/resend', [Auth\ConfirmEmailController::class, 'resend']);
321 Route::get('/register/confirm/{token}', [Auth\ConfirmEmailController::class, 'showAcceptForm']);
322 Route::post('/register/confirm/accept', [Auth\ConfirmEmailController::class, 'confirm']);
323 Route::post('/register', [Auth\RegisterController::class, 'postRegister']);
326 Route::post('/saml2/login', [Auth\Saml2Controller::class, 'login']);
327 Route::post('/saml2/logout', [Auth\Saml2Controller::class, 'logout']);
328 Route::get('/saml2/metadata', [Auth\Saml2Controller::class, 'metadata']);
329 Route::get('/saml2/sls', [Auth\Saml2Controller::class, 'sls']);
330 Route::post('/saml2/acs', [Auth\Saml2Controller::class, 'startAcs'])->withoutMiddleware([
332 ShareErrorsFromSession::class,
333 VerifyCsrfToken::class,
335 Route::get('/saml2/acs', [Auth\Saml2Controller::class, 'processAcs']);
338 Route::post('/oidc/login', [Auth\OidcController::class, 'login']);
339 Route::get('/oidc/callback', [Auth\OidcController::class, 'callback']);
341 // User invitation routes
342 Route::get('/register/invite/{token}', [Auth\UserInviteController::class, 'showSetPassword']);
343 Route::post('/register/invite/{token}', [Auth\UserInviteController::class, 'setPassword']);
345 // Password reset link request routes
346 Route::get('/password/email', [Auth\ForgotPasswordController::class, 'showLinkRequestForm']);
347 Route::post('/password/email', [Auth\ForgotPasswordController::class, 'sendResetLinkEmail']);
349 // Password reset routes
350 Route::get('/password/reset/{token}', [Auth\ResetPasswordController::class, 'showResetForm']);
351 Route::post('/password/reset', [Auth\ResetPasswordController::class, 'reset']);
354 Route::view('/help/wysiwyg', 'help.wysiwyg');
356 Route::fallback([HomeController::class, 'notFound'])->name('fallback');